From owner-freebsd-net@FreeBSD.ORG Fri Jan 25 01:07:59 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2967616A419 for ; Fri, 25 Jan 2008 01:07:59 +0000 (UTC) (envelope-from andrew.pogrebennyk@portaone.com) Received: from bugor.portaone.com (bugor.portaone.com [65.61.203.147]) by mx1.freebsd.org (Postfix) with ESMTP id 11CBC13C442 for ; Fri, 25 Jan 2008 01:07:58 +0000 (UTC) (envelope-from andrew.pogrebennyk@portaone.com) Received: from abilitily-barricade.volia.net ([77.123.128.59] helo=[192.168.178.14]) by bugor.portaone.com (8.11.3/8.11.3) with ESMTP id 1JICl9-000Crr-LF for freebsd-net@freebsd.org; Thu, 24 Jan 2008 16:49:31 -0800 Message-ID: <47993215.1010203@portaone.com> Date: Fri, 25 Jan 2008 02:49:25 +0200 From: Andrew Pogrebennyk User-Agent: Thunderbird 2.0.0.9 (X11/20071212) MIME-Version: 1.0 To: freebsd-net@freebsd.org Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: pptp question: managing routes on windows client connected to VPN X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 25 Jan 2008 01:07:59 -0000 Hi, I am using poptop-1.3.4 on FreeBSD 6.1. Right now when a windows client connects to VPN, it sets its end-point address as default gateway, that means all traffic goes through us. Is there some way to make windows create a specific route, instead of default route? Maybe it's only possible to get it to work only with the end-point tunnel address? If the above can't be done and we have to stick to default route, can we bandwidth-limit or clock certain traffic? I am not quite sure as to what interface firewall rules are to be applied. It may be a little OT, but I posted the question in poptop-server mailing list first and did not get any replies there... Thanks in advance. -- Sincerely, Andrew Pogrebennyk